-
Notifications
You must be signed in to change notification settings - Fork 559
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security fixes in GitHub actions for Unpinned Tags and Workflow yml that doesn't specifically define perms #1013
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…ouldn't get proper SHA for it. Put it back and will fix it later.
…disabled to test other steps
…d and push is commented out so can test it
… - Helm Chart disabled steps so only tests the changed task
…t any more. There was a fix for the Unpinned Tag in that section, so remove the task will also remove that security issue.
…elete whole thing. It does still have the security fix in it.
badrishc
approved these changes
Feb 18, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains fixes for two separate security issues found here: /~https://github.com/microsoft/garnet/security/code-scanning
For example: "uses: benchmark-action/github-action-benchmark@v1" becomes "uses: benchmark-action/github-action-benchmark@d48d326"
Each commit SHA was selected from the releases folder of each 3rd party tool. All of these were tested EXCEPT for line 74 of docker-linux.yml because that is the final build \ push step.
One of the tasks (Create PR task) in Helm needed fixed, but there was a security policy change that was preventing this task from even working, so I removed that task which also removed the initial security issue.
This is pretty simple fix where you just add this part to yml files that were missing it
permissions:
contents: read